Training on Clean Data but Getting Backdoored Models! A Poisoning Attack on Code Encoders
Yiran Xiao, Xiangyue Liu, Zhou Yang, Lili Bo, Xiaobing Sun
摘要
Transformer-based code encoders like CodeBERT learn general knowledge from vast amounts of unlabeled source code. These encoders can convert input code into meaningful representations (i.e., code embeddings) and support a series of downstream tasks. Specifically, users can fine-tune a code encoder on certain datasets and obtain strong model performance on corresponding tasks. Recent studies have exposed critical security vulnerabilities in this widely-adopted paradigm: attackers can inject backdoors into models by poisoning the fine-tuning datasets with carefully crafted triggers (e.g., dead code snippets), causing the model to produce attacker-specified outputs when these triggers are present.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong DetectionShenao Yan, Shen Wang, Yue Duan, Hanbin Hong 等USENIX Security 2024 · 被引用 63 次
- Multi-target Backdoor Attacks for Code Pre-trained ModelsYanzhou Li, Shangqing Liu, Kangjie Chen, Xiaofei Xie 等ACL 2023 · 被引用 28 次
- Robust Vulnerability Detection across Compilations: LLVM-IR vs. Assembly with Transformer ModelRony Shir, Priyanka Prakash Surve, Yuval Elovici, Asaf ShabtaiISSTA 2025 · 被引用 1 次
- You see what I want you to see: poisoning vulnerabilities in neural code searchYao Wan, Shijie Zhang, Hongyu Zhang, Yulei Sui 等FSE 2022 · 被引用 57 次
- Backdooring Neural Code SearchWeisong Sun, Yuchen Chen, Guanhong Tao, Chunrong Fang 等ACL 2023 · 被引用 18 次
